CVE-2026-26959Disclosure

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

ADB Explorer is a fluent UI for ADB on Windows. Versions 0.9.26020 and below fail to validate the integrity or authenticity of the ADB binary path specified in the ManualAdbPath setting before executing it, allowing arbitrary code execution with the privileges of the current user. An attacker can exploit this by crafting a malicious App.txt settings file that points ManualAdbPath to an arbitrary executable, then convincing a victim to launch the application with a command-line argument directing it to the malicious configuration directory. This vulnerability could be leveraged through social engineering tactics, such as distributing a shortcut bundled with a crafted settings file in an archive, resulting in RCE upon application startup. Thus issue has been fixed in version 0.9.26021.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-829

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 4 mentions (2026-02-20); latest day: 1
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-02-20: 4Mentions · 2026-02-25: 1Technical Details · 2026-02-20: 4Technical Details · 2026-02-25: 102-2002-25
Signal classification1 categories
Disclosure
5100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-204
Disclosure4
2026-02-251
Disclosure1
Full discourse5 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-26959 (CVSS:7.8, HIGH) is Awaiting Analysis. ADB Explorer is a fluent UI for ADB on Windows. Versions 0.9.26020 and below fail to validate the integrity or authentic..https://nvd.nist.gov/vuln/detail/CVE-2026-26959 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-26959, highlighting its high severity and that older ADB Explorer versions lack integrity validation, but it does not provide evidence of exploitation, a PoC, or a patch.

    0000029
    172 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26959 ADB Explorer is a fluent UI for ADB on Windows. Versions 0.9.26020 and below fail to validate the integrity or authenticity of the ADB binary path specified in the Ma… https://www.cve.org/CVERecord?id=CVE-2026-26959

    Post summary

    The text announces a vulnerability in ADB Explorer that allows improper validation of the ADB binary path, but it does not provide a PoC, exploit code, or any remediation details.

    0000093
    56.4K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-26959 📊 Severity: 7.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-26959 #CVE-2026-26959 #CVE #High #CyberSecurity #InfoSec https://t.co/xMQveOXTPe

    Post summary

    A new CVE (2026‑26959) is announced with a severity of 7.8; the tweet provides only high‑level details and a link to NVD, but no PoC, exploit, active exploitation, patch, or false‑positive information.

    0000024
    56 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26959 Arbitrary Code Execution in ADB Explorer via Malicious ManualAdbP... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26959 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet announces CVE-2026-26959, describing an arbitrary code execution flaw in ADB Explorer and linking to a vulnerability detail page, but provides no patch, exploit, or active exploitation information.

    0000037
    4.0K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Disclosure

    🚨 HIGH severity alert: Alex4SSB ADB-Explorer (<0.9.26021) lets attackers run code via malicious config files. Devs & IT pros, upgrade now to stay safe! 🛡️ https://radar.offseq.com/threat/cve-2026-26959-cwe-829-inclusion-of-functionality--f5a9dc71 #OffSeq #Infosec #Vulnerability https://t.co/e3znr8SO6W

    Post summary

    The tweet announces a high‑severity vulnerability (CVE‑2026‑26959) in Alex4SSB ADB‑Explorer, highlighting the potential for code execution via malicious config files, but provides no exploits, patches, or evidence of active attacks.

    0000041
    265 followersView on X

Explore more